Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
DETECTION ENGINEER (CORELIGHT) image - Rise Careers
Job details

DETECTION ENGINEER (CORELIGHT)

Company Overview

CriticalTilt blends 25+ years of specialized experience with a lean, responsive approach, delivering tailored solutions to government agencies and private sector clients. From navigating complex networks to adapting to new compliance demands, we understand our customers’ challenges and are primed to tilt the board towards success for their projects.


Position Overview

CriticalTilt, Inc. is seeking a highly skilled and experienced DETECTION ENGINEER (CORELIGHT) with a strong emphasis on network intrusion detection using the Corelight platform. The ideal candidate will possess a deep understanding of Zeek, Suricata, and YARA and measurable experience using Corelight sensors and the Fleet management platform. This role will be as resident engineer and subject-matter expert on the Customer’s site.  The DETECTION ENGINEER (CORELIGHT) will be responsible forefforts focused on implementation, configuration, use case development, and operational consulting by working closely with the customer to adapt visibility to mission.


Personnel Security Clearance (PSC)

Applicants must hold an active TS / SCI clearance with Full Scope Polygraph.


Responsibilities
  • Craft and maintain novel detection rules, algorithms and alerts that identify malicious and unusual activities
  • Conduct threat hunting activities to identify anomalies and potential threats
  • Leverage controlled environments for analyzing the operation of specific attacks and attacker techniques
  • Engage with Customer IT and cybersecurity personnel as well as Corelight support to produce and refine effective detections
  • Disseminate knowledge and discoveries regarding detections via internal- and external-facing documentation
  • Continuously improve intrusion detection capabilities based on emerging threats


Qualifications - General
  • 3+ years of experience in one or more of the following information security disciplines: detection engineering, threat hunting, incident response, security operations engineering
  • Demonstrated knowledge of information security tools such as Zeek, Suricata, and YARA
  • Demonstrated history of creating and maintaining detection rules and capabilities
  • Working knowledge of security investigation and incident response processes, particularly at enterprise-scale
  • Strong analytical skills related to detection engineering, including NSM/NDS systems, threat hunting, and threat identification
  • Familiarity with the capabilities of threat intel, malware analysis, and digital forensics
  • In-depth knowledge of networking concepts and protocols such as TCP/IP, HTTP, TLS, DNS, Kerberos, SMB
  • Experience working in an Agile work environment
  • Working knowledge of programming in at least two languages


Qualifications - Required
  • Administrate, Configure, and Optimize
  • Corelight Fleet Manager
  • Corelight Sensor(s)
  • Zeek
  • Suricata
  • YARA
  • Network
  • Operating System (Windows)
  • Operating System (Linux)
  • Cloud (AWS, Azure, GCP)
  • Software Development / Automation
  • Use-Case Analysis
  • Zeek
  • Suricata
  • YARA
  • Splunk
  • Elastic
  • Endpoint Detection and Response (EDR)
  • Specialization
  • Security Fundamentals
  • Security Operations
  • Threat Hunting
  • Incident Response
  • Network Security
  • Professional
  • Project Management
  • Documentation
  • Training / Knowledge Share Delivery
  • Cross-functional collaboration
  • Mentoring


Qualifications - Desired
  • Use-Case Analysis
  • Grafana
  • Humio
  • Specialization
  • Identity and Access Management
  • Governance and Compliance
  • Application Security
  • Mobile / IoT Security


Physical Demands and Work Environment

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this position. Reasonable accommodation may be made to enable individuals with disabilities to perform the functions.

While performing the duties of this position, the employee is regularly required to talk or hear. The employee frequently is required to use hands or fingers; handle or feel objects, tools, or controls. The employee is occasionally required to stand, walk; sit; reach with hands and arms; climb or balance, and stoop, kneel, crouch, or crawl. The employee must occasionally lift and/or move up to 50 pounds. Specific vision abilities required by this position include close vision, distance vision, color vision, peripheral vision, and the ability to adjust focus. The noise level in the work environment is usually moderate.


Note

This job description in no way states or implies that these are the only duties to be performed by the employee(s) incumbent in this position. Employees will be required to follow any other job-related instructions and to perform any other job-related duties requested by any person authorized to give instructions or assignments. All duties and responsibilities are essential functions and requirements and are subject to possible modification to reasonably accommodate individuals with disabilities. To perform this job successfully, the incumbents will possess the skills, aptitudes, and abilities to perform each duty proficiently. Some requirements may exclude individuals who pose a direct threat or significant risk to the health or safety of themselves or others. The requirements listed in this document are the minimum levels of knowledge, skills, or abilities. This document does not create an employment contract, implied or otherwise, other than an “at will” relationship.


Equal Opportunity Employer

CriticalTilt, Inc. is an Equal Opportunity Employer. Our policy is to provide equal employment to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, national origin, age, disability, marital status, veteran status and/or other status protected by applicable law.

Average salary estimate

$95000 / YEARLY (est.)
min
max
$80000K
$110000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Photo of the Rise User
WorkMotion Remote No location specified
Posted 9 days ago
Photo of the Rise User
Posted 5 days ago
Integres, LLC Remote Baltimore, Maryland, United States
Posted yesterday
Posted 4 days ago
Photo of the Rise User
Interapt Hybrid No location specified
Posted 2 days ago

in an ever-evolving technological landscape with scant resources, criticaltilt is your stalwart ally. we use our 25+ years of cybersecurity and it experience to tilt the board in your favor, so you're not just playing the game, you're winning it.

3 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
March 3, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!